PatchSiren

insumermodel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH insumermodel CVE published 2026-10-07

CVE-2026-104891

CVE-2026-104891: The mppx-condition-gate packages do not validate the relationship between the credential source and the payload, allowing an attacker to obtain free access to a route that should have been paid for by naming any qualifying address in the credential source. This vulnerability affects the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate. Defenders should asse [truncated]